Troubleshooting Tip: Downgrade of FortiOS fails due to BIOS check
| Description | This article describes downgrade issues due to an enhanced BIOS-level signature and file integrity checking. A solution is offered. |
| Scope | FortiGate running BIOS version 5000100, 6000100, or newer. |
| Solution | If a FortiGate device is running BIOS version 5000100 or 6000100 (or newer), the user will not be able to downgrade to v6.0, v6.2, or any other FortiOS versions below the ones listed here:
The device will not pass traffic and will display this error when booting up:
Booting OS...
It is recommended to upgrade FortiOS to a version that supports the BIOS security check to maximize the security posture of the device.
If the firmware does not support BIOS-level integrity checks, the BIOS prevents the boot or firmware installation. Refer to Troubleshooting Tip: Error messages 'This Firmware image didn't pass the signature verification.' and 'Firmware upload failed' when attempting to upgrade firmware image for details.
Warning: Changing the BIOS security level affects the overall security posture of the device and network. A lower BIOS security level could allow a user with administrative access to the FortiGate appliance to install and run modified, malicious firmware builds.
[C]: Configure TFTP parameters.
Enter C,R,T,F,I,B,Q,or H:
[S]: Set serial port baudrate.
Enter S,R,T,U,I,E,P,Q,or H:
[0]: Level 0 - Check image silently
Note: It is possible to check the security level currently set before rebooting the unit or after changing it with the command 'get system status.'
get system status
FortiGates with BIOS version 6.000105 and 6.000106 do not have the option of Security Level 0. In this case, upgrading or downgrading does not work. In such cases, the image to be imported using TFTP interrupts the boot process and loads the configuration from the previous version. More information about importing an image using TFTP: Technical Tip: Formatting and loading FortiGate firmware image using TFTP.
Starting with v7.0.16, v7.2.11, v7.4.6, and v7.6.1, the naming convention for Security Levels has been updated. The previous numerical levels 0, 1, and 2 are now represented as low, low, and high, respectively. More information about this change can be seen in this document: BIOS security Low and High level classification 7.0.16.
Some units, such as FortiGate 50G, 70G, 90G, 120G, and 200G, and their variants, have a 'Signed Firmware Hardware Switch' that requires physical access to change the BIOS security level (info on how to change it can be found on Technical Tip: How to change BIOS security level on FortiGate G series). If BIOS security level does not appear as an option for a physical device, see the product's datasheet to verify if a device includes this feature.
Related articles: Technical Tip: How to change BIOS security level on FortiGate G series |

